Skip to content
Otobiz
Sign in

How your data is kept apart.

What protects your conversations, your contact records, and the logins to your messaging channels.

Otobiz holds your customer conversations, your contact records, and the logins to your messaging channels. Your workspace is yours alone and no other business can see anything in it. Channel logins are stored encrypted. Anything consequential waits for a person to approve it, and every action is logged in a record nobody can edit.

What Otobiz does not have.

No certifications

Otobiz holds no SOC 2 report, no ISO certification, and no third-party audit, and displays no badge for any of them.

No single sign-on or directory provisioning

Otobiz does not connect to your own identity provider, and accounts are not provisioned automatically from your directory. Teammates are invited by email and managed inside the product.

No second factor inside Otobiz

Sign-in relies on the protections on your Google or Facebook account, a single-use link, or a one-time code sent to your email. Otobiz adds no separate authenticator step of its own.

The record stays inside the product

You can read, page through, and check the record of what was sent inside Otobiz. It does not export to a file or feed an outside logging system.

No choice of data region

Your data is stored in one cloud region. You cannot choose which, and there is no separate data centre for any market.

Message content is protected by separation, not by its own encryption

Channel logins are each encrypted individually. Message text, contact names, and phone numbers are protected by workspace separation, per-person access limits, masking, and encrypted storage, rather than by encrypting every field on its own.
What it does

What protects your data.

Ask to see any of these demonstrated.

Your workspace is yours alone

Your messages, your contacts, and your files belong to your workspace, and no other business can see them. The separation is enforced in the database itself, not by the screen you are looking at, so it holds even if something above it goes wrong.

  • No other business can read a message, a contact, or a file in your workspace
  • The separation holds even if something above it goes wrong
  • A request for a workspace you do not belong to is refused outright
  • Sign-in details are kept apart from workspace data

Your channel logins are stored encrypted

The access your WhatsApp, Instagram, Messenger, and Telegram accounts grant Otobiz is encrypted before it is stored, and the key that opens it is kept somewhere separate from the data. Each login is tied to the workspace it belongs to, so a copy lifted out of it cannot be opened. Nothing is ever written to a log or shown back to anyone.

  • Encrypted before it is stored, with the key kept separately
  • Tied to your workspace, so a copy taken elsewhere is useless
  • Never written to a log and never displayed again
  • Disconnecting a channel removes the stored access

Each person sees only what you allow

Owner, admin, and operator cover the usual split, with approvals limited to owners and admins and billing limited to owners. Beyond that you can restrict one person: which customers they see, whether they can export data, delete a contact, change settings, or edit automations. Phone numbers and email addresses can be masked so a restricted teammate never receives the real value.

  • A teammate can be limited to their own assigned customers
  • Phone numbers and email addresses masked before they reach the screen
  • Export, deletion, settings, integrations, and automations blockable per person
  • Access ends the moment you remove someone

Nothing sensitive sends without your approval

Campaigns, scheduled sends, reminders, and anything that writes to another system wait for a person. You approve the exact message that goes out, including the images, the links, and the product it points at. Change a word after approval and it comes back to you, and a double click or a retry never sends twice.

  • You approve the exact message, not a summary of it
  • An edit after approval needs approving again
  • A retry never sends the same message twice
  • Approvals expire instead of sitting open indefinitely

A complete record of what was sent and by whom

Every consequential action is logged: what was sent, to whom, who approved it, and when. Nothing in that record can be edited or deleted afterwards, and it is checked nightly for signs of tampering, with the owner told if anything looks wrong. You can read and check it inside the product at any time.

  • Every send, approval, and settings change recorded
  • Nothing in the record can be changed or removed after the fact
  • Checked nightly, with the owner told if anything looks wrong
  • An action and its record are saved together, so neither can exist alone

Only your real channels can deliver to you

Every incoming message is verified against the channel it claims to come from, and rejected when it does not check out. Which workspace it lands in is decided by the account that received it, never by anything the message says about itself.

  • Unverified traffic is rejected rather than accepted with a warning
  • Where a message lands is never decided by the sender

Deleting data actually deletes it

Deleting a contact removes their messages, attachments, and everything Otobiz learned about them. Deleting a workspace disconnects every channel at the provider, removes stored media, and deletes the workspace and everything belonging to it. Meta's own deletion requests are acted on rather than acknowledged and ignored.

  • Contact deletion removes messages, attachments, and stored facts
  • Workspace deletion disconnects channels before removing anything
  • Meta's deletion requests verified and acted on
  • Deletion is an owner action, and can be blocked for everyone else

Sign-in

Sign in with Google or Facebook, a single-use link, or a one-time code by email. Sessions expire. A social account joins an existing Otobiz account only when the email addresses match and the original address is verified, which closes the most common way accounts get taken over.

  • Google, Facebook, a single-use link, or a one-time email code
  • Sessions expire rather than lasting forever
  • A mismatched email address cannot claim an existing account

Encrypted storage and retained backups

Everything Otobiz stores is encrypted where it sits, and everything moving between your browser and Otobiz is encrypted in transit. Backups are retained, and the database cannot be deleted by accident.

  • Encrypted in storage and in transit
  • Backups retained
  • Protection against accidental deletion of the database

What reviewers ask.

Is our data separated from other businesses?

Yes. Your workspace is yours alone, and no other business can read a message, a contact, or a file in it. The separation is enforced in the database, so it holds even if something above it goes wrong.

Are you SOC 2 or ISO certified?

No. Otobiz holds no certification and displays no badge. We will demonstrate anything named here on request.

How are our WhatsApp and Telegram logins stored?

Encrypted, with the key held outside the application, and tied to your workspace so a copy taken elsewhere cannot be opened. Neither is ever written to a log or shown again.

Can we prove who approved a specific message?

Yes. Every send is logged with the approver and the exact message that went out, and you can check it inside the product at any time.

Can someone edit the record?

No. Nothing in it can be edited or deleted after the fact, and it is checked nightly, so a change made any other way would be detected.

Can we stop staff seeing customer phone numbers?

Yes. The number is masked before it reaches the screen, so a restricted teammate never receives the real value.

Do you support single sign-on?

No. Otobiz does not connect to your own identity provider. Sign-in is with Google or Facebook, a single-use link, or a one-time code by email.

Where is our data stored?

In one cloud region. You cannot choose which.

What happens to our data if we leave?

Deleting a workspace disconnects every channel at the provider, removes stored media, and deletes the workspace and everything belonging to it. Individual contacts can be deleted at any time.

How do we report a security issue?

Write to the support address on this site with the details and you will get an answer. There is no bug bounty programme.